Effective 2026-10-10. This policy covers orviqa.dev and the Orviqa application.
This service is operated by VECTRADB CONSULTING LTD (registered number 17053787), registered address 45 Peets Bridge Drive, St. Helens, England, WA9 5AQ.
For the purposes of UK GDPR and EU GDPR we are the data controller for the data described below. To exercise any of the rights set out under “Your rights”, email support@orviqa.dev.
When you create an account: your name, your email address, and your profile image URL, taken either from what you type or from your GitHub or Google profile. If you sign up with a password we store a scrypt hash of it. We never store the password itself and cannot recover it.
When you connect GitHub: your GitHub login, an OAuth access token, and the scopes that token carries. Signing in with GitHub requests read:user, user:email, public_repo. public_repo is not read-only: GitHub bundles write access into it and there is no narrower scope that still allows reading a public repository. Orviqa’s analysis only ever reads. Anything that writes on your behalf uses a separate token you connect yourself, per channel.
When you use the product: the repositories you add and their public GitHub metadata; the analyses, drafts, plans and project pages generated for you; a ledger of AI usage recording token counts and costs per run; and your workspace membership and role.
When you buy tokens: a Stripe customer identifier, a record of the purchase, and a credit ledger of grants, purchases and consumption. We never see or store your card details. Payment happens on Stripe’s checkout and card data does not pass through our servers.
This is the part most worth reading. This list is generated from the live configuration of this deployment, so it describes what actually happens rather than what was true when the policy was written.
The Anthropic disclosure is the material one for this product. When you analyse a repository we send that repository’s file contents — actual source code and documentation — together with its metadata. This is how the analysis works; there is no version of it that does not involve sending the code to a model. Anthropic's commercial terms prohibit training models on content sent through their API, so your repository content is not used to train their models. How long they retain it is governed by their data processing addendum.
The application is hosted by Vercel. The database is hosted by Supabase, on AWS in eu-central-1 (Frankfurt, Germany). Some of the processors listed above are based in the United States, which means data described here is transferred there.
One gap worth stating plainly: if you stop using the service without deleting your account, we do not currently delete it for you. Nothing expires on a schedule. If you want your data gone, delete the account.
If you have no account and you are reading a project page, the directory or the blog, this is the whole of what happens. When you view a public project page or click a link out of one, we store an event containing which page and which project, an anonymous visitor identifier, any utm_* parameters in the URL you arrived on, the hostname of the referring page, and a timestamp.
What we deliberately do not record:
news.ycombinator.com, not the path, because a path frequently contains a search query or a document title.This is unusually little, and it is deliberate. The purpose is to let a maintainer see whether their page is working, not to build a profile of you.
One cookie, sf_vid: 128 random bits, opaque, with nothing encoded in it, a 90-day lifetime, and the HttpOnly and SameSite=Lax flags. Its only purpose is to avoid counting one person twice. It is issued only on public pages: if you are signed in and using the product, you are not given one.
If you generate a public project page, its content becomes publicly visible and will be indexed by search engines. That content is written from your repository, which is already public.
Directory listings may also be created from public GitHub metadata for repositories nobody has claimed. These are labelled as unclaimed, are marked noindex so search engines are not offered them, and contain only data GitHub already publishes. If one concerns a repository you maintain and you want it removed, email support@orviqa.dev.
Nothing is published to an external channel on your behalf without you approving the specific draft. Every publish records who approved it and who sent it.
We hold no third-party security certification — no SOC 2, no ISO 27001 — and this policy does not imply otherwise. More detail on access and data handling is on the security page.
Under UK GDPR and EU GDPR you have the right to access your data, to correct it, to have it erased, to restrict or object to processing, and to data portability. You also have the right to complain to a supervisory authority.
How to exercise them: email support@orviqa.dev. We will respond within one month.
Most of this is self-serve in the product. Disconnecting GitHub in Settings removes the stored token immediately. Turning off personalisation in Settings genuinely stops your browsing contributing to your recommendations; it is not a cosmetic switch.
Deleting your account is self-serve, in Settings. Before anything happens it shows you exactly what will go: which workspaces, how many repositories, and the URLs of any published project pages that will stop resolving. Three things survive it, and each for a stated reason.
One case is refused rather than honoured immediately: if you are the only owner of a workspace other people are using, deleting your account would lock them out of it permanently. The product tells you which workspace and how many people, and asks you to make someone else an owner first. Your right to erasure does not extend to their data.
If any of that does not fit your situation, email support@orviqa.dev and we will handle it by hand.
We will post any changes on this page and update the effective date above.
See also: terms of service · security and data handling